We need to document what the inbound and outbound vulnerability management process is. * Comparable from CCC: [governance/security-response-policies.md at main · confidential-computing/governance (github.com)](https://github.com/confidential-computing/governance/blob/main/security-response-policies.md) * Microsoft comparable (less relevant for a foundation project): [ebpf-for-windows/SECURITY.md at master · microsoft/ebpf-for-windows (github.com)](https://github.com/microsoft/ebpf-for-windows/blob/master/docs/SECURITY.md)) * LFx Security- https://docs.linuxfoundation.org/lfx/security/overview There is work in progress linked at bottom of https://github.com/ossf/wg-vulnerability-disclosures
We need to document what the inbound and outbound vulnerability management process is.
There is work in progress linked at bottom of https://github.com/ossf/wg-vulnerability-disclosures